Security practices

What we actually do to protect the data firms put in Law Warfare CRM. This page states our current practices — nothing aspirational, nothing we don't hold.

Isolation by architecture

Every firm runs its own dedicated installation with its own database. No shared application, no shared tables, no multi-tenant queries. Another firm's outage or breach surface is not yours.

Encryption in transit

All connections to your installation — browser, mobile, integrations — are encrypted with TLS. Backups are encrypted.

Accounts and authentication

Per-user accounts with hashed credentials. Two-factor authentication (authenticator app or SMS) is available for admin accounts. Sessions are server-side and can be ended by logging out.

Activity logging

Application activity in your installation is logged to each client's timeline — bookings, messages, document actions, AI actions. AI features log what they read and what they produced.

No training on your data

Customer data is never used to train AI models — ours or anyone else's — and we do not permit our AI providers to retain it for training.

Backups and updates

Nightly encrypted backups, monitored infrastructure, and platform updates applied to every installation as they ship.

Certifications: we currently hold no third-party security certification, audit, or attestation (no SOC 2, no ISO 27001), and we will not claim one on any page, deck, or ad until it is complete. When that changes, it will be stated here first.

Questions, or something to report? Contact us — security reports are read first.